On Tue, Apr 11, 2000 at 01:29:49PM +1000, Steven Kerr wrote:
> I just need a pointer with IP Masq/IP Chains as I am confused
> regarding when these tools would be used.
>
> Am I correct in saying that:
>
> IP Masquarading allows hosts to project themselves onto another
> network (private or public) with a different IP address. This would
> normally be used with some sort of 'routing' software such as IP
> Chains
right enough
the routing software (ipchains) is just used to declare which traffic
streams will be masqueraded - the masquerading code (not ipchains)
does the real trickery
> IP Chains --> IP Forwarding is used to route /forward IP packets, say,
> across a firewall according to some rule sets that would be definable.
yes, ipchains is just an implementation of a "rule set".
ip forwarding itself is a fairly simple thing that doesn't necessarily
require the ability to firewall (ie. filter packets)
> So if that is the case, what kernel parameters would need to be set to
> masquarade a internal (private) LAN onto the internet via a Linux
> Server.
the minimum would be adding the forwarding rule:
"source = internal network & destination = external world
-> masquerade me"
with ipchains, thats:
ipchains -A forward -s 10.0.0.0/8 -j MASQ
(assuming your internal network is 10.0.0.0/8)
and then allowing traffic in and out:
ipchains -P input ACCEPT
ipchains -P output ACCEPT
since you are playing with the tables anyway, you will probably want
to be a lot more careful than that with your rules
if you are on a debian system, the "ipmasq" package does a very good
job of building these rules without you needing to do anything
--
- Gus
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text